{"title":"对费斯特尔变种的新量子攻击","authors":"Qiufu Lan, Jian Zou, Jichen Wei","doi":"10.1007/s11128-025-04852-0","DOIUrl":null,"url":null,"abstract":"<div><p>Simon’s algorithm is a period-finding algorithm that can provide an exponential speedup compared to the classical algorithm. It has already been widely used in the quantum cryptanalysis of some cryptographic primitives. This paper investigates the applications of Simon’s algorithm in the security analysis of several Feistel variants: MARS-F, Skipjack-B-F, 4F-function, and 2F-function schemes. Firstly, we give a 2<i>d</i>-round quantum distinguisher for <i>d</i>-branch MARS-F. Secondly, a <span>\\((d^2 - 1)\\)</span>-round quantum distinguisher is built for <i>d</i>-branch Skipjack-B-F. Thirdly, we construct a 10-round and a 6-round quantum distinguisher for 4F-function and 2F-function, respectively. Based on these quantum distinguishers, we can build some quantum key-recovery attacks on these Feistel variants. We denote <i>n</i> as the bit length of a branch. In the first place, for 3<i>d</i>-round MARS-F with <i>d</i> branches, a key-recovery attack is constructed with the time complexity of <span>\\(O\\left( n2^{dn/2}\\right) \\)</span>. In the second place, for <span>\\((d^2 + d - 1)\\)</span>-round Skipjack-B-F with <i>d</i> branches, we present a key-recovery attack with the time complexity of <span>\\(O\\left( n2^{dn/2}\\right) \\)</span>. At last, the key can be recovered with the time complexities of <span>\\(O\\left( n2^{5n}\\right) \\)</span> and <span>\\(O\\left( n2^{3n/2}\\right) \\)</span> for 14-round 4F-function and 8-round 2F-function, respectively.</p></div>","PeriodicalId":746,"journal":{"name":"Quantum Information Processing","volume":"24 8","pages":""},"PeriodicalIF":2.2000,"publicationDate":"2025-07-21","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"New quantum attacks on some Feistel variants\",\"authors\":\"Qiufu Lan, Jian Zou, Jichen Wei\",\"doi\":\"10.1007/s11128-025-04852-0\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"<div><p>Simon’s algorithm is a period-finding algorithm that can provide an exponential speedup compared to the classical algorithm. It has already been widely used in the quantum cryptanalysis of some cryptographic primitives. This paper investigates the applications of Simon’s algorithm in the security analysis of several Feistel variants: MARS-F, Skipjack-B-F, 4F-function, and 2F-function schemes. Firstly, we give a 2<i>d</i>-round quantum distinguisher for <i>d</i>-branch MARS-F. Secondly, a <span>\\\\((d^2 - 1)\\\\)</span>-round quantum distinguisher is built for <i>d</i>-branch Skipjack-B-F. Thirdly, we construct a 10-round and a 6-round quantum distinguisher for 4F-function and 2F-function, respectively. Based on these quantum distinguishers, we can build some quantum key-recovery attacks on these Feistel variants. We denote <i>n</i> as the bit length of a branch. In the first place, for 3<i>d</i>-round MARS-F with <i>d</i> branches, a key-recovery attack is constructed with the time complexity of <span>\\\\(O\\\\left( n2^{dn/2}\\\\right) \\\\)</span>. In the second place, for <span>\\\\((d^2 + d - 1)\\\\)</span>-round Skipjack-B-F with <i>d</i> branches, we present a key-recovery attack with the time complexity of <span>\\\\(O\\\\left( n2^{dn/2}\\\\right) \\\\)</span>. At last, the key can be recovered with the time complexities of <span>\\\\(O\\\\left( n2^{5n}\\\\right) \\\\)</span> and <span>\\\\(O\\\\left( n2^{3n/2}\\\\right) \\\\)</span> for 14-round 4F-function and 8-round 2F-function, respectively.</p></div>\",\"PeriodicalId\":746,\"journal\":{\"name\":\"Quantum Information Processing\",\"volume\":\"24 8\",\"pages\":\"\"},\"PeriodicalIF\":2.2000,\"publicationDate\":\"2025-07-21\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Quantum Information Processing\",\"FirstCategoryId\":\"101\",\"ListUrlMain\":\"https://link.springer.com/article/10.1007/s11128-025-04852-0\",\"RegionNum\":3,\"RegionCategory\":\"物理与天体物理\",\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q1\",\"JCRName\":\"PHYSICS, MATHEMATICAL\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Quantum Information Processing","FirstCategoryId":"101","ListUrlMain":"https://link.springer.com/article/10.1007/s11128-025-04852-0","RegionNum":3,"RegionCategory":"物理与天体物理","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"PHYSICS, MATHEMATICAL","Score":null,"Total":0}
Simon’s algorithm is a period-finding algorithm that can provide an exponential speedup compared to the classical algorithm. It has already been widely used in the quantum cryptanalysis of some cryptographic primitives. This paper investigates the applications of Simon’s algorithm in the security analysis of several Feistel variants: MARS-F, Skipjack-B-F, 4F-function, and 2F-function schemes. Firstly, we give a 2d-round quantum distinguisher for d-branch MARS-F. Secondly, a \((d^2 - 1)\)-round quantum distinguisher is built for d-branch Skipjack-B-F. Thirdly, we construct a 10-round and a 6-round quantum distinguisher for 4F-function and 2F-function, respectively. Based on these quantum distinguishers, we can build some quantum key-recovery attacks on these Feistel variants. We denote n as the bit length of a branch. In the first place, for 3d-round MARS-F with d branches, a key-recovery attack is constructed with the time complexity of \(O\left( n2^{dn/2}\right) \). In the second place, for \((d^2 + d - 1)\)-round Skipjack-B-F with d branches, we present a key-recovery attack with the time complexity of \(O\left( n2^{dn/2}\right) \). At last, the key can be recovered with the time complexities of \(O\left( n2^{5n}\right) \) and \(O\left( n2^{3n/2}\right) \) for 14-round 4F-function and 8-round 2F-function, respectively.
期刊介绍:
Quantum Information Processing is a high-impact, international journal publishing cutting-edge experimental and theoretical research in all areas of Quantum Information Science. Topics of interest include quantum cryptography and communications, entanglement and discord, quantum algorithms, quantum error correction and fault tolerance, quantum computer science, quantum imaging and sensing, and experimental platforms for quantum information. Quantum Information Processing supports and inspires research by providing a comprehensive peer review process, and broadcasting high quality results in a range of formats. These include original papers, letters, broadly focused perspectives, comprehensive review articles, book reviews, and special topical issues. The journal is particularly interested in papers detailing and demonstrating quantum information protocols for cryptography, communications, computation, and sensing.